
CYBER.ORG Range
Product by Cyber Innovation Center
The Bottom Line
Partially. While The Learning Standard has not yet evaluated CYBER.ORG Range, its virtual sandbox approach aligns well with experiential learning principles. Providing a secure environment to practice cybersecurity skills allows students to apply theoretical knowledge safely. However, its effectiveness depends heavily on accompanying teacher-led instruction rather than standalone, self-paced learning.
Pros
- Offers a sandboxed virtual environment that supports experiential learning without real-world risks.
- Provides educators with structured lesson plans to scaffold complex cybersecurity concepts.
- Uses short instructional videos to reduce cognitive overload when introducing digital safety basics.
- Connects theoretical skills to concrete career pathways through active profile exploration.
Cons
- Relies heavily on external teacher facilitation rather than built-in, adaptive feedback loops.
- Lacks automated assessments to measure individual student mastery of hands-on technical skills.
- Does not utilize spaced repetition algorithms to ensure long-term retention of technical terminology.
What Do We Know About CYBER.ORG Range?
CYBER.ORG Range is effective for hands-on application of cybersecurity concepts, provided your child uses it alongside guided teacher instruction. This platform is not a self-contained learning game or a plug-and-play app. Instead, it acts as a virtual laboratory. Your child logs into a secure, cloud-based environment to practice technical skills, like defending against simulated cyber attacks or configuring networks, without risking your home computer or data. Educational research strongly supports this type of experiential learning, as interacting with authentic tools builds deeper mental models than reading alone. However, the platform itself does not teach the material adaptively. It lacks automated feedback mechanisms or mastery-based progression. If your child makes a mistake during a simulation, they rely on their classroom teacher to diagnose the error and provide corrective instruction. Because of this, it is highly valuable as an extension of a school curriculum but holds limited value as a standalone, self-paced learning tool at home.
How Does CYBER.ORG Range Work?
CYBER.ORG Range utilizes an experiential, problem-based learning approach through cloud-hosted virtual machines. Students log into a browser-based portal that simulates a real-world operating system and network environment. Inside this sandbox, they receive specific technical scenarios or challenges designed by their teacher using the platform's provided curriculum. Students execute commands, configure security settings, and analyze vulnerabilities within the virtual space. The mechanics mimic actual IT industry workflows. Because the environment is isolated, students can safely execute malicious code or intentionally break system configurations to observe the consequences. Alongside the practical range, the platform delivers direct instruction via short, targeted video modules covering foundational digital safety and career exploration. Teachers monitor progression manually, using the platform's supplemental lesson plans to guide classroom discussions and evaluate student success based on task completion rather than automated in-app grading.
Strengths and tradeoffs of CYBER.ORG Range
The biggest strength of CYBER.ORG Range is its authentic, risk-free environment for applying complex technical skills, while its biggest weakness is the complete absence of built-in, adaptive feedback. Experiential application is crucial for mastering computer science. By allowing students to interact with real operating systems and command-line interfaces, the platform bridges the gap between abstract concepts and practical execution. This hands-on approach builds robust cognitive schemas that static textbooks cannot replicate. Furthermore, the inclusion of worked examples in the provided teacher resources helps educators scaffold complex tasks for novices. However, the lack of automated feedback limits its independent utility. Learning science dictates that immediate, corrective feedback is essential for correcting misconceptions during skill acquisition. Because CYBER.ORG Range relies entirely on the classroom teacher to evaluate student actions within the virtual machines, students may practice incorrect procedures if the teacher's attention is divided. Additionally, the platform does not incorporate spaced retrieval practice for its theoretical content, meaning teachers must independently design quizzes or review sessions to ensure students retain the vocabulary and protocols over time.
Who Might Benefit From CYBER.ORG Range?
CYBER.ORG Range is best for middle and high school students enrolled in formal computer science or cybersecurity classes under the guidance of a trained educator. While the platform offers resources for K-12, the virtual range environment requires foundational technical knowledge and structured facilitation to be effective. It is an ideal resource for schools looking to provide authentic lab experiences without investing in expensive hardware or risking their local network security. It is not suitable for individual students seeking a self-paced coding or tech tutorial at home.
Data Transparency
Does Not Meet Data Transparency Standard
CYBER.ORG Range does not meet our data transparency standard. Its privacy policy does not describe restrictions on sharing children's data.
17 of 35 checks passed
Evaluated September 2026
View privacy policy →View all 35 checks
Parent Access5/8
Does the policy mention parents specifically?
“Parents of homeschooled K-12 students”
Can parents view their child's data?
“Policy is silent on parents viewing their child's specific data.”
Can parents modify their child's data?
“Policy is silent on parents modifying their child's specific data.”
Can parents delete their child's account?
“Policy is silent on parents deleting their child's account.”
Is there a dedicated Children's Privacy section?
“8. Children’s Privacy”
Does it reference COPPA compliance?
“compliance with the Children’s Online Privacy Protection Rule (16 CFR Part 312 or “ COPPA ”)”
Does it reference FERPA compliance?
“Family Education Rights and Privacy (34 CFR Part 99 or “ FERPA ”)”
Is parental consent required for child accounts?
“Where required by law, verifiable parental consent is obtained prior to account creation.”
Data Portability1/5
Can users access their personal data?
“Individuals have the right to: i. Request access to collected data”
Can users download/export their data?
“Policy is silent on users downloading or exporting their data.”
Is there a self-service data access tool?
“Access requests must be submitted via email, not a self-service tool.”
Is a specific data format mentioned for export?
“No specific data format for export is mentioned in the policy.”
Is there an API for data access?
“Policy does not mention an API for user data access.”
Data Minimization2/6
Is data collection itemized?
“i. Account Registration Data: a. First and last name b. Email address c. Name of school...”
Can the app be used without a real name?
“Usernames, passwords, and nicknames are randomly generated and 100% anonymized for Students.”
Can the app be used without an email?
“Policy lists email address as collected but does not mention use without an email.”
Does it state collection is limited to what is necessary?
“Policy does not explicitly state that data collection is limited to what is necessary.”
Is IP address anonymized or truncated?
“Policy mentions collecting IP address but does not state it is anonymized or truncated.”
Is location tracking explicitly excluded?
“Location tracking is not explicitly excluded; approximate geographic location is collected.”
Third-Party Protection5/7
Does it explicitly state no selling of data?
“We never sell data to anyone for any purpose.”
Are third-party providers named?
“we use trusted third-party service providers, including... Heroku (Salesforce)... Vercel...”
Are providers contractually restricted?
“These third-party service providers are permitted to process data solely to provide services”
No-targeted-advertising commitment?
“We do not use cookies or tokens for advertising, third-party behavioral tracking, or profiling.”
Is AI/ML data sharing addressed?
“AI/ML data sharing is not addressed in the policy.”
Child-specific sharing restriction?
“Policy is silent on child-specific data sharing restrictions beyond general non-sharing rules.”
Cookies/tracking limited or opt-out?
“Users can manage cookie preferences via browser settings.”
Deletion & Retention1/5
Can users delete their account?
“You may request deletion of your data by contacting [email protected]”
Self-service deletion mechanism?
“Deletion requires contacting an email address; no self-service mechanism is mentioned.”
Specific data retention timeline?
“No specific data retention timeline is provided in the policy.”
Auto-deletion of inactive accounts?
“Policy is silent on the auto-deletion of inactive accounts.”
Post-deletion handling described?
“Post-deletion handling is not specifically described.”
Advertising3/4
Advertising model explicitly disclosed?
“We do not use or share data for advertising purposes, including displaying advertisements.”
Free from third-party advertisements?
“We do not use or share data for advertising purposes, including displaying advertisements.”
Children excluded from ad targeting?
“We do not use or share data for advertising purposes, including displaying advertisements.”
Ad-free option available?
“Policy does not mention an ad-free option because the entire service does not display ads.”
What This Means
The policy review did not meet our data transparency standard. The checks above show the documented findings and unknowns. A missing statement does not establish how the app handles data in practice.
About this evaluation: Based on automated analysis of CYBER.ORG Range's privacy policy using the Common Sense Privacy Program framework. Results describe the policy disclosures we assessed; unknown checks are excluded from scores. Privacy policies can change. This review reflects the version we analyzed and does not determine legal compliance.
Sources and review method
TLS combines product information and editorial analysis to explain how CYBER.ORG Range works, its tradeoffs, and the questions to ask before choosing it. Product features, an instructional rationale and evidence of learning outcomes are different kinds of information.
Formal Learning Standard assessment: not yet completed. Data Transparency findings are reported separately and do not establish learning effectiveness. Read our methodology.
Frequently Asked Questions About CYBER.ORG Range
Is CYBER.ORG Range free?
Yes, CYBER.ORG Range is completely free for K-12 educators and students in the United States. Funding is provided through a grant from the Cybersecurity and Infrastructure Security Agency (CISA), meaning schools can access the virtual environments and curriculum without any licensing fees. This removes financial barriers for districts wanting to implement robust technical education.
Is CYBER.ORG Range good for elementary students?
Primarily, no. While the platform provides basic cyber safety videos suitable for younger children, the core virtual range environment is strictly designed for middle and high school students. The complex technical interfaces, command-line operations, and problem-solving required in the virtual machines exceed the cognitive load appropriate for early elementary grades.
What does CYBER.ORG Range teach?
CYBER.ORG Range teaches practical cybersecurity skills, network configuration, and digital citizenship. Students learn how to identify system vulnerabilities, understand basic encryption principles, practice ethical hacking techniques in a secure environment, and explore technical career pathways. It focuses heavily on applying theoretical computer science concepts to simulated real-world scenarios.
Is CYBER.ORG Range safe for kids?
Yes, it is highly secure by design. The platform operates as a completely isolated, cloud-based sandbox. When students practice mitigating cyber threats or handling simulated malware, it happens within a closed virtual machine. This ensures that no actions taken within the educational range can infect their actual computer, compromise personal data, or impact the school network.
Has The Learning Standard evaluated CYBER.ORG Range?
No, CYBER.ORG Range is pending evaluation and has not yet been rated by our team. Once evaluated, our researchers will determine its efficacy based on our rigorous pedagogical rubric. You can read more about our evidence-based review process on our methodology page.
Is CYBER.ORG Range COPPA compliant?
The reviewed privacy policy references COPPA. A policy reference alone does not establish COPPA compliance. Policy review note: compliance with the Children’s Online Privacy Protection Rule (16 CFR Part 312 or “ COPPA ”)
Is CYBER.ORG Range FERPA compliant?
The reviewed privacy policy references FERPA. A policy reference alone does not establish FERPA compliance. Policy review note: Family Education Rights and Privacy (34 CFR Part 99 or “ FERPA ”)
Does CYBER.ORG Range have a children's privacy policy?
The reviewed policy includes a dedicated children's privacy section. Policy review note: 8. Children’s Privacy
Does CYBER.ORG Range sell student data?
The reviewed policy states that the app does not sell data. This is a policy statement; actual data practices were not verified. Policy review note: We never sell data to anyone for any purpose.
Can you delete your data from CYBER.ORG Range?
The reviewed privacy policy describes account deletion. We have not tested the deletion process. Policy review note: You may request deletion of your data by contacting [email protected]
Follow TLS Research
Subscribe to future TLS research updates: app reviews, findings, and what the evidence shows.
Screenshots

Take Action
For CYBER.ORG Range
If you represent Cyber Innovation Center and have a correction or new evidence, send the relevant source so we can review and update this page.
Submit a correctionDetails
- Pricing
- Free
- Website
- Visit site